{"id":"CVE-2026-13082","summary":"GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets","details":"GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets.\n\nThe random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string.\n\nThe built-in rand function is unsuitable for security applications because it is predictable and reversible.","modified":"2026-08-12T03:51:09.732021175Z","published":"2026-07-17T12:54:07.177Z","database_specific":{"cwe_ids":["CWE-338","CWE-804"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13082.json","cna_assigner":"CPANSec"},"references":[{"type":"WEB","url":"https://cpan.org/modules"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2025-40916"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13082.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13082"},{"type":"FIX","url":"https://security.metacpan.org/patches/G/GD-SecurityImage/1.75/CVE-2026-13082-r1.patch"},{"type":"PACKAGE","url":"https://github.com/burak/CPAN-GD-SecurityImage"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/burak/cpan-gd-securityimage","events":[{"introduced":"0"},{"last_affected":"1257deef621d94fe6919b33e21f5e89ef895a2f6"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"1.75"}]}}],"versions":["v1.75","v1.74","v1.73","v0.70","v1.68"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13082.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}